Splunk Search

Which indexes count towards the 500mb daily limit?

paycorp
Engager

Hello,

I was wondering which indexes are included in the daily 500mb limit of the free version?

Is it just the main one or ALL of them including _internal and os etc...?

Thanks,

Tags (2)
0 Karma

Ayn
Legend

Indexing in all non-internal indexes counts against the license, except for summary indexing which is 'free'.

Non-internal indexes are generally the ones not starting with an underscore when you look at a fresh Splunk installation (that is, you can't create your own index with a leading underscore and get free indexing there 😉 )

Ayn
Legend

Hopefully someone from Splunk can chime in with an authoritative answer here.

My guess would be that internal status of indexes is hardcoded, otherwise it would be all too easy to give yourself free indexing.

0 Karma

jonuwz
Influencer

Obvious next question .....

What makes an internal index internal ? 🙂 Is it hardcoded in the binary ?

Do any add-ons ship with extra internal indexes ?

While, isInternal is exposed in

https://localhost:8089/servicesNS/nobody/search/data/indexes/

there's no setter function in the POST.

Academic research only of course...

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...